- INFORMATION COLLECTION PRACTICES. 2.1 Types of Information Collected.
(a) We use Contact Data to (i) provide Newsletters to Users who opt-in, (ii) to create and manage accounts for Users, (iii) provide customer service to Users, (iv) analyze our Users’ usage of our Services, (v) send Users information about the Company and its Services, and (vi) contact Users for other legitimate business purposes, (b) We use Usage Data to (i) send users suggestions on how they can further reduce their energy consumption and save more (ii) offer additional hardware, accessories or upgraded service offerings to further their benefit received with their platform subscription
(c) If you purchase a license directly from the Company, we collect Financial Information to charge Users for the Paid Services ordered, but we do not store or retain any of your Financial Information, except for the last four digits of your credit card. Your Financial Information is processed directly by the applicable third party processor through an API integration. (d) We collect your Transaction History so that we can accurately track the purchases you have placed and answer any questions you may have in connection with any charges made to your credit cards. (e) We collect Traffic Data for the purpose of providing and improving the Service. (f) We collect Usage Data to analyze energy consumption. (g) We collect Log Data for the purpose of providing and improving the Service, and to advertise to you through re-remarketers. (h) We may link or combine the Personal Information we collect and/or receive about you and the Traffic Data we collect automatically during your visit to our website or use of certain of our Services. This allows us to provide you with a personalized experience and helps us to continually work to improve our Services. 2.3 Retention of Information Collected. We will only retain your Personal Information for as long as necessary to fulfill the purposes we collected it for, including for our provision of the Services, the purposes of our accessed legitimate business interests, and satisfying any legal or reporting requirements. For clarity, retention periods may be extended if we are required to preserve your information or data because of litigation, investigations and other similar proceedings, or if a longer retention period is required or permitted by applicable law. 2.4 Third Party Data Processors.
(a) naak engages certain third parties that may process data submitted to naak to perform certain business-related functions and to increase the functionality of our Services. For example, we use third parties for credit card processing and shipping purchases in the provision of our Services. Third party companies provide various other services to us, such as monitoring and analyzing how our Services are used or performing. When we engage another company to perform such functions, we may provide them with information, including Personal Information and Traffic Data in connection with their performance of such functions. These third parties may analyze the data we provide, combine that data with publicly available data, and provide us with access to their analysis and reports. The chart below lists our third party data processors, a description of the service they provide, types of Users from whom the processors may process data, and the type of data processed by each processor. The chart may be updated by naak from time to time:
Types of Users Categories of Data
Third Party Processors End User
Financial Data Google LLC (for analytics) X X X X WordPress (website) X X X X
Stripe (for payment processing)
(only when purchasing directly from naak) X X
The Rocket Science Group DBA Mailchimp (for Newsletters) X X X
(b) To the extent these third parties have access to any of your data, and especially your Personal Information or a combination of data that is deemed to be personally identifiable, please know that they are contractually (i) limited to only use this data to perform specific tasks on our behalf and (ii) obligated not to disclose or use your information for any other purpose. (c) For your information, Google LLC recommends installing the Google Analytics Opt- out Browser Add-on – https://tools.google.com/dlpage/gaoptout – for your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics. For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://www.google.com/intl/en/policies/privacy/ 2.5 Additional Controllers.
(a) Users that have purchased licenses from a Third-Party Reseller (and not from the Company directly), are managed directly by that Third-Party Reseller, which has full unrestricted access to all data provided in connection with a User’s use of naak Connect. Users should contact their Third-Party Reseller directly to obtain their privacy policies. (b) All User, Limited Administrator and Unlimited Administrator data is shared directly with CarbonTRACK PTY LTD (“CarbonTRACK”), the licensor of the naak Connect technology. CarbonTRACK can be contacted directly at 104 Burwood Road, Hawthorn, Victoria 3122, Australia, to obtain their privacy policies.
- YOUR RIGHTS AND THE COMPANY’S LEGAL BASIS FOR COLLECTING PERSONAL
INFORMATION. 3.1 User Rights. Users who wish to correct, update, change, or erase the Personal Information they submit to Company may do so through their account or by contacting the Company in writing. 3.2 Information Requests. Upon request, we will provide you with information about whether we hold any of your personal information. Again, you may access, correct or request deletion of your personal information by logging into your account, or by contacting us. We will respond to your request within 30 days. 3.3 The Company’s Legal Basis for Processing Your Personal Information. We process Personal
Information of our Users for the following reasons: (a) Processing Personal Information is necessary for entering into and performing a contract with you. In order to perform obligations that we undertake in providing a Service to you, or in order to take steps at your request to enter into a contract with us, it will be necessary for us to process your Personal Information. (b) Processing Personal Information is necessary for the purposes of our legitimate business interests. Either we, or a third party, will need to process your Personal Information for the purposes of our (or a third party’s) legitimate interests, provided we have established that those interests are not overridden by your rights and freedoms, including your right to have your Personal Information protected. Our legitimate interests include responding to requests and inquiries from you or a third party, optimizing our website and customer experience, optimizing our managed energy services modules, informing you about our
products and services and ensuring that our operations are conducted in an appropriate and efficient manner. (c) Processing Personal Information is necessary to obtain your consent. In some circumstances, we may ask for your consent to process your Personal Information in a particular way. To the extent that we are processing your Personal Information based on your consent, you have the right to withdraw your consent at any time. You can do this by contacting us through the methods provided below.
5.2 Compliance with Opting-Out. In compliance with the Controlling the Assault of Non- Solicited Pornography And Marketing Act of 2003, Company will honor User unsubscribe requests within ten (10) days of receipt of such request.
- SECURITY OF YOUR PERSONAL INFORMATION. 6.1 Industry Standards. The security of your Personal Information is important to us. We follow generally accepted industry standards to help protect your Personal Information including without limitation: (a) limiting access to your Personal Information to those of our employees who require it to provide services to you; (b) requiring employees to sign confidentiality agreements to protect customer and other confidential information; (c) ensuring that third-party service providers sign confidentiality agreements to maintain the confidentiality of your Personal Information and not to use it for any unauthorized purposes; and (d) storing your Personal Information in secure computer systems which protect it from unauthorized access or use. 6.2 No Guarantee. No method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to protect your Personal Information, we cannot guarantee its absolute security. 6.3 Passwords. If a password is used to protect your account and Personal Information, it is your
- LINKS. We may link to websites, including those of our subsidiaries and third-party content providers, which have different privacy policies and practices from those disclosed here. We assume no responsibility for the policies or practices of such linked sites, and encourage you to become acquainted with them prior to use.
- CHILDREN’S PRIVACY. Only persons age 18 or older have permission to access our Service. We do not knowingly collect personally identifiable information from children. If you are a parent or guardian and you learn that your child has, somehow, provided us with Personal Information, please contact us. If we become aware that we have collected Personal Information from a child, we take steps to remove that information from our servers.
- YOUR CANADIAN PRIVACY RIGHTS. For our Canadian users, please know that this
Address: 112 Kent Street, Ottawa, ON K1A 1H3 Phone: (613) 995-8210 Toll-free: (800) 282-1376 Facsimile: (613) 947-6850 TTY: (613) 992-9190 Website: www.priv.gc.ca/en/
- EEA COMPLIANCE. 12.1 Compliance with EEA Requirements. If you are located in the European Economic Area (“EEA”), we will comply with applicable legal requirements providing adequate protection for the transfer of Personal Information to recipients in countries outside of the EEA, including the USA. In all such cases, we will only transfer your personal data if: (a) The country to which the personal data will be transferred has been granted a European Commission adequacy decision; (b) The recipient of the personal data is located in the U.S. and has certified to the EU- U.S. Privacy Shield Framework; or (c) We have put in place appropriate safeguards with respect to the transfer, for example the EU Model Clauses. 12.2 Safeguard Requests by EEA Users. If you are located in the EEA, you may request a copy of the safeguards that we have put in place in respect of any applicable transfers of personal data by contacting us as described in Section 14 below. 12.3 EEA User Rights. If you are located in the EEA, you may have the following rights in respect
of your Personal Information that we hold: (a) Right of access. The right to obtain access to your Personal Information along with certain information. (b) Right of portability. The right to receive your Personal Information in a commonly used format and to have it ported to another data controller. (c) Right to rectification. The right to obtain rectification of your personal information without undue delay where that personal information is inaccurate or incomplete. (d) Right to erasure. The right to obtain the erasure of your Personal Information without undue delay in certain circumstances, such as where the Personal Information is no longer necessary in relation to the purposes for which it was collected or processed. (e) Right to restriction. The right to obtain the restriction of the processing undertaken by us on your Personal Information in certain circumstances, such as where the accuracy of the Personal Information is contested by you, for a period enabling us to verify the accuracy of that Personal Information. (f) Right to object. The right to object, on grounds relating to your particular situation, to the processing of your Personal Information, and to object to processing of your Personal Information for direct marketing purposes, to the extent it is related to such direct marketing. 12.4 Exercising Rights. For additional information, assistance with any problems accessing your information or if you wish to exercise one of these rights set forth in Section 12.3, please contact us at firstname.lastname@example.org